

How to apply
Closing date: 4 October 2026 · 16 days left
Send your CV and cover letter to
sr.recruitment-officer@ghazanfarbank.comPlease quote reference GB/EAD/62 in the subject line.
Job summary
- Reference
- GB/EAD/62
- No. of vacancies
- 1
- Published
- 17 September 2026
- Closing date
- 4 October 2026
- Country
- Afghanistan
- Province
- Kabul
- Functional area
- Business & Finance › Banking
- Education
- Bachelor's degree
- Experience level
- Mid level
- Years of experience
- 3 years
- Employment type
- Full time
- Contract type
- Permanent
- Probation period
- Three months
- Gender
- Male
- Languages
- Dari, Pashto, English
- Salary
- As per company salary scale
About the job
The IT Security Analyst is responsible for protecting the Bank’s information assets, systems, and infrastructure by implementing, monitoring, and enhancing information security controls. The role ensures that cybersecurity risks are effectively identified, managed, and escalated in line with Basel principles, regulatory requirements, and the Bank’s risk appetite.
The position supports operational IT security under the Dy-CIO while ensuring indepndent risk oversight and incident escalation to the CRO
Duties & responsibilities
A. Information Security Operations
Monitor IT systems, networks, and applications for security threats and vulnerabilities.
Implement and maintain security controls, tools, and configurations.
Support secure system configurations across CBS, applications, servers, and networks.
Ensure compliance with approved IT security standards and policies.
B. Cyber Risk & Incident Management
Detect, analyze, and respond to information security incidents and cyber threats.
Escalate material security incidents, cyber risks, and control weaknesses to the CRO in a timely manner.
Support incident investigation, root-cause analysis, and remediation actions.
Maintain incident logs and prepare incident reports.
C. Governance, Risk & Compliance Support
Support the implementation of the Bank’s Information Security Policy, IT governance framework, and risk controls.
Coordinate with Risk Management to:
Identify IT and cyber risks
Support risk assessments and KRIs
Align controls with the Bank’s risk appetite
Support Compliance requirements related to data protection, access controls, and regulatory expectations.
D. Access Control & Security Monitoring
Monitor and review user access rights to critical systems (including CBS).
Support periodic access reviews and segregation of duties controls.
Ensure timely removal or modification of access for staff movements and terminations.
E. Vulnerability Management & Security Testing
Conduct or coordinate vulnerability assessments and security testing.
Track remediation of identified vulnerabilities.
Support implementation of security patches and system hardening.
F. Audit & Regulatory Support
Act as a focal point for IT security matters during:
Internal Audit
External Audit
Regulatory examinations
Support closure of IT security-related audit findings and regulatory observations.
G. Awareness & Capacity Building
Support IT security awareness initiatives and training programs for staff.
Promote a strong security culture and compliance with security policies.
7. Authority & Escalation
Recommend security improvements and corrective actions.
Escalate high-risk security incidents and systemic weaknesses to Dy-CIO and CRO.
No authority to override business or system decisions without approval.
Job requirements
Education
Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, or a related field.
Professional Certifications (Preferred)
CISSP, CISM, CISA, CEH, ISO 27001, or equivalent information security certifications.
Experience
Minimum 3–5 years of experiencein IT security, cybersecurity, or information risk management.
Experience in banking, financial services, or regulated environments is a strong advantage.
Submission guideline
Applicants who meet the above requirements are invited to submit their updated Curriculum Vitae (CV) or Resume to sr.recruitment-officer@ghazanfarbank.com .
Please ensure that you include the position title and vacancy announcement number in the email subject line ( IT Security Analyst GB/EAD/62 ).
Applications that do not follow this format will not be considered.
More jobs from this organization



